Group-level reporting office
A group-level reporting office pools the internal whistleblowing function at one central group company, which acts as a mandated third party for the affiliated entities under Section 14 (1) of the German Whistleblower Protection Act (HinSchG).
A group-level reporting office exists where the affiliated companies do not each run their own internal reporting office, but a central unit – typically group compliance at the parent company or a shared service entity – receives and handles reports on behalf of several group companies. In Germany this model rests on Section 14 (1) sentence 1 HinSchG, which allows an employer to entrust a third party with the duties of the internal reporting office; the explanatory memorandum expressly names another group company as such a third party. It must be distinguished from the joint reporting office under Section 14 (2) HinSchG, which is open only to employers with 50 to 249 employees and implements Article 8 (6) of Directive (EU) 2019/1937.
Whether this broad German reading is compatible with EU law remains contested. In guidance given to member states (statements by DG Justice in 2021) the European Commission took the view that every legal entity with 50 or more employees must maintain its own internal reporting channel; a group-wide channel may only exist in addition to the local one, and the reporting person must be free to choose where to report. The German legislator did not follow that interpretation. There is still no ruling by the Court of Justice of the European Union on the point, so groups that centralise reporting entirely carry a residual risk should the stricter reading prevail.
Regardless of that dispute, the duties of each individual employer remain untouched. Under Section 14 (1) sentence 2 HinSchG, mandating a third party does not release the employer from taking appropriate measures itself to stop an identified breach; accountability and the exposure to fines stay with the subsidiary. The central unit must act independently and with the necessary expertise (Section 15 HinSchG), observe the confidentiality requirement of Section 8 HinSchG and meet the deadlines of Section 17 HinSchG. Data protection also needs a proper basis, because the GDPR grants no group privilege for sharing report data. In practice a hybrid design works best: a group-wide channel combined with locally named contact persons and a documented right of the reporting person to choose.
Legal Basis
Sections 14 (1) and 14 (2) HinSchG; Sections 8, 15, 17 HinSchG; Article 8 (3) to (6) of Directive (EU) 2019/1937
Practical Example
A mechanical engineering group with a holding company and six German subsidiaries – four of them with more than 250 employees – wants to pool the reporting office at group compliance. The compliance officer signs a written mandate agreement with each subsidiary under Section 14 (1) HinSchG plus a data processing agreement setting out access rights, retention periods and how findings are passed to the local management. In addition, every subsidiary names a local contact who can receive reports directly; the intranet lists both routes as well as the federal external reporting office. The group is therefore compliant even if the European Commission's stricter reading prevails, and responsibility for follow-up measures demonstrably stays with the company concerned.